Wifiphisher: Ένας Έλληνας προγραμματιστής ασφαλείας κυκλοφόρησε ένα εργαλείο που μπορεί να κάνει την απόκτηση κωδικών πρόσβασης απο ένα network WiFi easier. How; Let's look at the tool from the beginning.
The Wifiphisher is a security tool that quickly locates automated phishing attacks against WPA networks in order to gain the secret passphrase. It is a tool of social engineering attacks that unlike other methods that do not include any brute forcing. It's an easy way to get WPA passwords.
The Wifiphisher works with Kali Linux and is distributed under MIT license.
From the victim's side, the attack is in three phases:
- The victim stops connecting to his or her access point. Wifiphisher approaches all Appliances that are connected to a wifi by sending deauth packets to the client from the access point, from the access point to the client, as well as to the broadcast address.
- The victim is associated with a malicious access point. Wifiphisher "smells" the router login page and copies the target access point settings. It then creates a malicious wireless access point that targets the target page. It also sets up a NAT / DHCP server and forwards the correct ports. As a result, due to interference, customers will begin to connect to the malicious access point. After this phase, the victim is MiTMed (man-in-the-middle).
- The victim is led to a realistic router settings page. wifiphisher uses a minimal web server that responds to HTTP and HTTPS requests. Once the victim requests a web page, the wifiphisher will respond with a realistic fake page asking for WPA password confirmation due to a router firmware upgrade.
The tool developer is the George Hatzisofroniou and is intended for penetration testing purposes.
theoretically does not work in wepwpa2;
paidia kalispera .. mporeite na mou peite pws 8a to tre3w ayto sto linux ??